Privacy Policy

Privacy Policy

Document Version: XP.EN.01.03

1. General Information

Xpand IT is committed to protecting your privacy. This Privacy Policy governs our practices for collecting, using, retaining, and disclosing personal data. This policy applies to information we collect through the use of our websites, the subscription to our services or products, whether free or paid, participation in marketing campaigns, such as events and webinars, or whenever you interact with Xpand IT.

We update this Privacy Policy periodically and recommend that you review it regularly.

If our data processing practices change significantly, we will notify you of those changes before using your personal data for new purposes and, where applicable, give you the opportunity to object or withhold consent to those new processing activities.

This Privacy Policy has been prepared in accordance with the General Data Protection Regulation (GDPR) and other applicable European and Portuguese personal data protection laws.

2. General Principles of our Privacy Policy

Xpand Solutions – Informática e Novas Tecnologias, Lda., owner of the Xpand IT brand, is the entity responsible for processing personal data.

In the context of your relationship with us, whether through the use of our website, the provision of your personal data, or any other interaction involving the processing of personal data, we undertake to act in accordance with this Privacy Policy, based on the following principles:

i. Only duly authorized individuals access and process the personal data necessary to perform their duties and solely for legitimate and authorized purposes;

ii. We consider the security of personal data a priority and regularly review the implemented measures, considering technological developments and identified risks;

iii. We recognize that personal data belongs to the respective data subjects, with Xpand IT acting as the controller of that data under applicable law;

iv. We promote good practices in Privacy, Data Protection, and Information Security, reviewing them continuously as part of ongoing improvement.

3. Definitions

Personal data: any information relating to an identified or identifiable natural person (“Data Subject”). An identifiable natural person is one who can be identified, directly or indirectly, by reference to an identifier such as a name, identification number, location data, online identifier, or one or more factors specific to that person’s physical, physiological, genetic, mental, economic, cultural, or social identity.

Processing: any operation or set of operations performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination, or otherwise making available, alignment or combination, restriction, erasure, or destruction.

Consent: any freely given, specific, informed, and unambiguous indication of the data subject’s wishes by which the data subject, by a statement or by a clear affirmative action, agrees to the processing of personal data relating to them.

Websites: all Xpand IT websites under its main domains, namely xpand-it.com.

Cookies: small text files stored on your device, such as a computer, tablet, or mobile phone, when you visit a website, allowing the device to be recognized and certain information about your use to be stored.

4. What personal data do we collect?

We collect only the categories of personal data that are adequate, relevant, and necessary for the purposes described in this Privacy Policy, namely:

  • Contact details, such as name, email address, phone number, country, and city;
  • Professional and profile data, such as job title, company, and other information related to professional activity;
  • Photographs;
  • Billing data, including tax identification number;
  • Software-related preferences, including your use and interests;
  • Data relating to browsing behavior on our websites;
  • IP addresses, URLs visited, and other information related to the use of our websites and services;
  • Cookies, under the terms of our Cookie Policy;
  • Data relating to academic background and professional experience.

The personal data collected is processed electronically and stored in secure databases, in strict compliance with applicable Personal Data Protection laws and Information Security standards.

We process your personal data exclusively for specific, explicit, and legitimate purposes determined at the time of collection. Personal data will not subsequently be processed in a manner incompatible with those purposes, except where permitted by the GDPR, including for archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes.

Although Xpand IT’s activities do not generally involve the intentional processing of special categories of personal data (“sensitive data”), if such processing occurs on an exceptional basis, it will only take place in the cases provided for in Article 9(2) of the GDPR and subject to the adoption of enhanced safeguards appropriate to the risk.

5. How do we collect your personal data?

We collect personal data directly from data subjects through the following activities and interaction channels:

ActivityData   
WebsiteAll websitesCookies
Webinar registration formsContact details and professional data
Training registration formsContact details, professional data, and billing data
Event registration formsContact details, professional data, and photographs taken during the event
Newsletter subscriptionContact details
Content downloads, such as e-books, case studies, or other materialsContact details and professional data
Access to online supportContact details
Product SandboxesContact details and usage data
Job application formContact details, résumé, and other relevant professional information
Contact requestsContact details
Digital surveys and questionnairesContact details and software-related preferences
Paper surveys and questionnairesContact details and software-related preferences
Participation in eventsContact details and software-related preferences
Recruitment activities, including when you submit an unsolicited application or apply directly for a position advertised on our website; through job fairs, events, or a third party; when you apply through referrals provided by our employees; and during interviewsContact details, professional data, academic background, professional experience, and other information relevant to the recruitment process

In all cases, collection is limited to what is necessary for the applicable purpose and carried out in accordance with the principles of transparency, data minimization, and purpose limitation.

6. How do we use the data collected?

Purposes

The personal data we collect is processed for the purposes listed below, always in an appropriate and proportionate manner and limited to what is necessary:

PurposePersonal data processed
Marketing and communication campaignsContact details, photographs, and software-related preferences
Commercial activities, business development, and marketingContact details, professional data, and software-related preferences
Management of the contractual relationship, where applicableContact details
Sending important communications about changes to our terms, conditions, and policiesContact details
Identifying and exploring new market opportunitiesProfessional data
Processing transactions and sending related information, including purchase confirmations and billingContact details and billing data
Improving our products and servicesUsage data and browsing behavior
Improving the browsing experience on our websitesCookies
Recruitment and selectionAcademic background, professional experience, and other information relevant to the recruitment process
Improving the user experienceAnonymized usage data and aggregated product metrics
Resolving technical issues and providing supportAnonymized usage data and aggregated product metrics

Lawful bases

Under Article 13(1)(c) of the GDPR, the processing of personal data is based on one or more lawful bases, depending on the specific purpose of the processing and the context in which the data is collected:

PurposeApplicable lawful basis
Marketing and communication campaignsConsent of the data subject for electronic communications / Xpand IT’s legitimate interest for non-electronic communications
Commercial activities, business development, and marketingXpand IT’s legitimate interest
Management of the contractual relationship, where applicablePerformance of a contract or pre-contractual steps
Sending important communications about changes to our terms, conditions, and policiesCompliance with legal obligations
Identifying and exploring new market opportunitiesXpand IT’s legitimate interest
Processing transactions and sending related information, including purchase confirmations and billingPerformance of a contract / Compliance with legal obligations
Improving our products and servicesXpand IT’s legitimate interest
Improving the browsing experience on our websitesConsent of the data subject for non-essential cookies / Xpand IT’s legitimate interest for essential cookies
Recruitment and selectionPre-contractual steps / Consent of the data subject
Improving the user experienceXpand IT’s legitimate interest
Resolving technical issues and providing supportPerformance of a contract / Xpand IT’s legitimate interest

7. Personal data of minors

Xpand IT’s products and services are not intended for minors.

Xpand IT does not intentionally collect personal data from minors. If we become aware that personal data of a minor has been collected without the legally required consent, we will take appropriate measures to delete that data without undue delay.

If you become aware of such a situation, please contact us using the channels indicated in the “Contact us about privacy matters” section.

8. Security of personal data

We use appropriate technical and organizational measures to protect your personal data against unauthorized, accidental, or unlawful destruction, loss, alteration, disclosure, or access, as well as against any other form of unlawful processing.

The personal data provided is stored in secure systems and environments protected by appropriate security mechanisms designed to prevent unauthorized access, use, alteration, or disclosure.

We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including where applicable:

i. The pseudonymization and encryption of personal data;

ii. The ability to ensure ongoing confidentiality, integrity, availability, and resilience of processing systems and services;

iii. The ability to restore the availability of and access to personal data in a timely manner in the event of a physical or technical incident;

iv. A process for regularly evaluating, analyzing, and verifying the effectiveness of the technical and organizational measures implemented to ensure the security of personal data processing.

9. Sharing and disclosure of personal data

We do not share or disclose your personal data to third parties except in the cases described in this Privacy Policy or where necessary to comply with legal, regulatory, or contractual obligations.

Whenever your personal data is shared with third parties acting on our behalf, we ensure that they adopt appropriate data security and protection measures equivalent to those applied by Xpand IT. We also ensure that the necessary mechanisms are implemented to safeguard the rights of data subjects.

Depending on the purpose involved, these third parties may include, in particular, IT and hosting service providers, including cloud and hosting providers; marketing, communication, and customer relationship management platforms; entities responsible for issuing invoices and processing payments; professional advisors, including legal, accounting, or audit advisors; and public or judicial authorities, where legally required.

Social media features: Our websites may include features provided by social media networks, such as sharing buttons, links to institutional profiles, or other interactive components. These features may collect certain data, such as your IP address or information about your browsing, and may also use cookies.

These features may be hosted by third-party entities or directly on our websites. Your interactions with these features are governed by the privacy policies of the entities responsible for making them available.

Links to third-party websites: Our websites may contain links to third-party websites whose privacy practices are independent from those of Xpand IT. If you provide personal data through those websites, the relevant data will be processed in accordance with the privacy policies of those entities. We recommend that you read the relevant privacy policies before providing any personal information.

Testimonials: We may publish customer testimonials regarding our products and services. Any testimonial that includes personal data will be published only with the prior consent of the relevant data subject. If you wish to change or remove your testimonial, you may contact us using the channels indicated in this Privacy Policy.

Sharing based on consent: Where necessary, we will share your personal data with third parties only after obtaining your prior, specific, and informed consent.

Compliance with legal obligations: We reserve the right to use or disclose personal data whenever required by law, court order, or legitimate request from a competent authority, as well as where necessary to defend our rights, prevent fraud, or protect the safety of people and property. Where legally permitted, we will seek to inform the data subject in advance of such disclosure.

10. Rights of data subjects

Under the GDPR, data subjects have the following rights:

i. Right of Access – you have the right to obtain confirmation as to whether or not your personal data is being processed and, where that is the case, to access that data and obtain information about, among other things, the purposes of processing, the categories of personal data concerned, and the recipients of the data. You also have the right to obtain a copy of your personal data undergoing processing. Additional copies may be subject to a reasonable fee based on administrative costs. If the request is made electronically and unless otherwise indicated, the information will be provided in a commonly used electronic format.

ii. Right to Rectification – you have the right to obtain, without undue delay, the rectification of inaccurate personal data concerning you and to request that incomplete personal data be completed.

iii. Right to Erasure – also known as the “right to be forgotten,” you have the right to request the erasure of your personal data without undue delay whenever one of the situations provided for in the GDPR applies.

iv. Right to Withdraw Consent – whenever processing is based on consent, the data subject has the right to withdraw consent at any time, without affecting the lawfulness of processing carried out based on consent before its withdrawal.

v. Right to Object – you have the right to object, on grounds relating to your particular situation, to the processing of your personal data in the cases provided for in the GDPR. You also have the right to object at any time to the processing of your data for direct marketing purposes, in which case we will immediately stop processing it for that purpose.

vi. Right to Data Portability – you have the right to receive the personal data you provided to us in a structured, commonly used, and machine-readable format, as well as the right to transmit that data to another organization, where applicable under the GDPR.

vii. Right to Restriction of Processing – you have the right to obtain restriction of the processing of your personal data in certain circumstances provided for in the GDPR, including when you contest the accuracy of the personal data, for the period necessary for us to verify its accuracy, when the processing is unlawful, or when you have exercised your right to object.

viii. Right to Lodge a Complaint – the data subject has the right to lodge a complaint with a supervisory authority. In Portugal, the competent supervisory authority is the Comissão Nacional de Proteção de Dados (CNPD).

To exercise any of the rights referred to above, you should use the contact details indicated in section 14 of this Privacy Policy.

Requests submitted will be reviewed and answered without undue delay and, in any case, within a maximum period of one month from receipt, in accordance with the GDPR. Where necessary, considering the complexity and number of requests, this period may be extended by an additional two months, and the data subject will be duly informed of the extension and the reasons for it.

11. Retention of personal data

The retention period for personal data varies depending on the purpose for which the data is processed and the respective legal bases.

Xpand IT retains personal data only for the period necessary to fulfill the purposes for which it was collected, satisfy legal, regulatory, or contractual obligations, and ensure the exercise or defense of rights in legal proceedings.

As a rule, Xpand IT will retain your personal data for a maximum period of 6 (six) years after the last contact with the data subject, unless there is a legal obligation or legitimate reason justifying retention for a longer period.

Personal data included in contracts, invoices, or other documents subject to legal archiving obligations will be retained for the legally applicable periods.

After the applicable retention periods have expired, personal data will be securely deleted or anonymized, unless its retention is required by law.

12. International transfer of personal data

Where necessary, we may transfer personal data to entities located outside the European Economic Area (EEA) or to international organizations.

In such situations, we will ensure that transfers are carried out in strict compliance with applicable personal data protection laws, including by verifying the existence of an adequate level of protection in the destination country or implementing the appropriate safeguards provided for in the GDPR.

In addition, we will adopt the necessary measures to ensure the security of the transferred data, ensuring that recipient entities are contractually required to protect the confidentiality, integrity, and availability of personal data and to use it solely for the authorized purposes.

13. Use of cookies

For more information about the use of cookies on our websites, please see our Cookie Policy.

14. Contact details for privacy matters

If you have any questions, requests, or concerns relating to this Privacy Policy or the processing of your personal data, you may contact our Data Protection Officer through the following channels:

Email: [email protected]

Phone Number: +351 21 896 7150

Address: Praça Príncipe Perfeito, No. 2, 3rd floor, 1990-278 Lisbon, Portugal

15. Changes to the Privacy Policy

Xpand IT reserves the right to amend this Privacy Policy at any time to reflect legislative, regulatory, operational, or technological changes.

Any changes will be published on our websites and will take effect from the respective publication date.

We recommend that you review this Privacy Policy periodically to stay informed about how we protect and process your personal data.

Continued use of our websites, products, or services after changes are published indicates acknowledgment of the updated version of the Privacy Policy.